291 results for “topic:suricata”
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
:star: :star: Distributed tcpdump for cloud native environments :star: :star:
A Suricata based NDR distribution
Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等
Tenzir is the data pipeline engine for security teams.
Scirius is a web application for Suricata ruleset management and threat hunting.
QNSM is network security monitoring framework based on DPDK.
Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search
This project is a SIEM with SIRP and Threat Intel, all in one.
Pulled Pork for Snort and Suricata rule management (from Google code)
Evasion by machine code de-optimization.
Nmap&Zmap特征识别,绕过IDS探测
A website and framework for testing NIDS detection
A Suricata Docker image.
The tool for updating your Suricata rules.
idstools: Snort and Suricata Rule and Event Utilities in Python (Including a Rule Update Tool)
Suricata IDS/IPS log analytics using the Elastic Stack.
An All-In-One home intrusion detection system (IDS) solution for the Raspberry PI.
A curated list of awesome things related to Suricata
CVE-2020-16898 (Bad Neighbor) Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule
gonids is a library to parse IDS rules, with a focus primarily on Suricata rule compatibility. There is a discussion forum available that you can join on Google Groups: https://groups.google.com/forum/#!topic/gonids/
Suricata rules for network anomaly detection
DynamiteNSM is a free Network Security Monitor developed by Dynamite Analytics to enable network visibility and advanced cyber threat detection
How to setup a honeypot with an IDS, ELK and TLS traffic inspection
I developed a rigorous cybersecurity project portfolio on mock clients covering NIST, audits, Linux, SQL, assets, threats, vulnerabilities, detection, incident response, escalation, Wireshark, tcpdump, IDS (Suricata), SIEM (Splunk, Chronicle), and Python automation.
Suricata安装部署&丢包优化&性能调优&规则调整&Pfring设置
Fully automated host & network intrusion detection platform. Detects malware from behavioural patterns rather than signatures and enables deeper visibility than legacy tools.
A lightweight tool to score network traffic and flag anomalies
Cyber Defence Monitoring Course Suite :: Suricata, Arkime (and others in the past)